# Elastic Stack

**URL:** https://discuss.elastic.co/c/elastic-stack/81.md?page=642

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 643

---

## [Monitoring of multiple unlicensed Elasticsearch clusters on a single-node Elastic box with Metricbeat](https://discuss.elastic.co/t/monitoring-of-multiple-unlicensed-elasticsearch-clusters-on-a-single-node-elastic-box-with-metricbeat/324801)

<div class="topic-metadata">

**Author:** [@foss4ever](https://discuss.elastic.co/u/foss4ever)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 9:46am UTC](https://discuss.elastic.co/t/monitoring-of-multiple-unlicensed-elasticsearch-clusters-on-a-single-node-elastic-box-with-metricbeat/324801 "2023-02-07T09:46:38Z")

</div>

I have successfully set up a single-node Elastic box with Elasticsearch, Kibana and Metricbeat to monitor two separate Elastic clusters. Now I am reading in a couple of topics on this forum that you can only monitor one…

---

## [Will attribute script make elasticsearch write slower?](https://discuss.elastic.co/t/will-attribute-script-make-elasticsearch-write-slower/324212)

<div class="topic-metadata">

**Author:** [@robocon20x](https://discuss.elastic.co/u/robocon20x)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 9:34am UTC](https://discuss.elastic.co/t/will-attribute-script-make-elasticsearch-write-slower/324212 "2023-02-07T09:34:20Z")

</div>

Hi everyone, i am going to create many script columns for my index, will this make elasticsearch write to this index slower than before, because it will create many columns per document of index?

---

## [Adding certificate to keystore](https://discuss.elastic.co/t/adding-certificate-to-keystore/323941)

<div class="topic-metadata">

**Author:** [@Mistral](https://discuss.elastic.co/u/Mistral)\
**Replies:** 12\
**Last updated:** [February 7, 2023, 9:10am UTC](https://discuss.elastic.co/t/adding-certificate-to-keystore/323941 "2023-02-07T09:10:07Z")

</div>

Hi ! Using Elastic 8.6.0 here I started over a clean installation of Elastic and immediatly tried to overwrite the self-generate certificate of Elastic with my organization certificate (which is a certificate generate b…

---

## [Can i use deployment after expiring 14 days free trial?](https://discuss.elastic.co/t/can-i-use-deployment-after-expiring-14-days-free-trial/324867)

<div class="topic-metadata">

**Author:** [@parkJ](https://discuss.elastic.co/u/parkJ)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 8:46am UTC](https://discuss.elastic.co/t/can-i-use-deployment-after-expiring-14-days-free-trial/324867 "2023-02-07T08:46:43Z")

</div>

I'm using elasticsearch 14days free trial now. If it'll be expired, it'll be renewed automatically? and can i use my deployment using now will be locked?

---

## [DeadLetterQueue Configration](https://discuss.elastic.co/t/deadletterqueue-configration/324869)

<div class="topic-metadata">

**Author:** [@Venkata\_Sai\_K](https://discuss.elastic.co/u/Venkata_Sai_K)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 7:55am UTC](https://discuss.elastic.co/t/deadletterqueue-configration/324869 "2023-02-07T07:55:40Z")

</div>

I have done Deadletter queue configration in one file and given to that as volume for the docker service , everything we have dockerized it and here are my files persistent-queue and dlq config pipeline.batch.size: 125 …

---

## [How to migrate/move indices from Elastic cloud to Elastic stand alone in remote server](https://discuss.elastic.co/t/how-to-migrate-move-indices-from-elastic-cloud-to-elastic-stand-alone-in-remote-server/324600)

<div class="topic-metadata">

**Author:** [@sriteja\_chebrolu](https://discuss.elastic.co/u/sriteja_chebrolu)\
**Replies:** 4\
**Last updated:** [February 7, 2023, 7:44am UTC](https://discuss.elastic.co/t/how-to-migrate-move-indices-from-elastic-cloud-to-elastic-stand-alone-in-remote-server/324600 "2023-02-07T07:44:55Z")

</div>

Please help me to migrate/move indices from Elastic cloud to Elastic stand alone in remote server. Please provide the steps. I tried with reindexing but getting "not whitelisted in reindex.remote.whitelist" error. I …

---

## [Unable to import kibana saved objectki](https://discuss.elastic.co/t/unable-to-import-kibana-saved-objectki/324815)

<div class="topic-metadata">

**Author:** [@PRASHANT\_MEHTA](https://discuss.elastic.co/u/PRASHANT_MEHTA)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 7:44am UTC](https://discuss.elastic.co/t/unable-to-import-kibana-saved-objectki/324815 "2023-02-07T07:44:09Z")

</div>

Hello All, I'm unable to import the saved object in kibana.Earlier the saved object size was around 700 kb.Now I have many visuals and dashboards and now the size is around 1.6 mb of saved object.When importing saved o…

---

## [Fleet hosts settings](https://discuss.elastic.co/t/fleet-hosts-settings/324821)

<div class="topic-metadata">

**Author:** [@adrien\_moreau](https://discuss.elastic.co/u/adrien_moreau)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 7:20am UTC](https://discuss.elastic.co/t/fleet-hosts-settings/324821 "2023-02-07T07:20:18Z")

</div>

Hello, I am running elk in a self managed environment and my question concerns the following fleet setting: xpack.fleet.agents.elasticsearch.hosts This parameter is described in documentation as: "Hostnames used by E…

---

## [Saved Object: Internal Server Error](https://discuss.elastic.co/t/saved-object-internal-server-error/324856)

<div class="topic-metadata">

**Author:** [@mike21](https://discuss.elastic.co/u/mike21)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 7:00am UTC](https://discuss.elastic.co/t/saved-object-internal-server-error/324856 "2023-02-07T07:00:39Z")

</div>

Firstly, there are around 7 saved objects, I was trying to import a new object pattern, with the existing one object, but removed a few criteria, Then the import has failed, and all the saved objects were missing. Th…

---

## [How to parse the wrapper logs which contains timestamp value at each line](https://discuss.elastic.co/t/how-to-parse-the-wrapper-logs-which-contains-timestamp-value-at-each-line/324341)

<div class="topic-metadata">

**Author:** [@sai7276p](https://discuss.elastic.co/u/sai7276p)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 6:58am UTC](https://discuss.elastic.co/t/how-to-parse-the-wrapper-logs-which-contains-timestamp-value-at-each-line/324341 "2023-02-07T06:58:05Z")

</div>

I have created grok pattern for single line entries, but I just want to remove the timestamp and extra fields before the java stack trace lines,,, to register a full stack trace to a single field 'MSG' "(%{LOGLEVEL:leve…

---

## [Logstash not inserted data into elasticsearch](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737)

<div class="topic-metadata">

**Author:** [@mohanss08](https://discuss.elastic.co/u/mohanss08)\
**Replies:** 6\
**Last updated:** [February 7, 2023, 6:45am UTC](https://discuss.elastic.co/t/logstash-not-inserted-data-into-elasticsearch/324737 "2023-02-07T06:45:24Z")

</div>

Hello Team, I had Elasticsearch, Logstash and Kibana v7.16.2 with xpack security based login enabled, Yesterday i had upgraded my ELK versions to 8.6.1 using my docker-compose file. Current problem: My logstash fetched…

---

## [How to perform GeoDistanceSort on a nested field using ES-8.5.3 JavaClient](https://discuss.elastic.co/t/how-to-perform-geodistancesort-on-a-nested-field-using-es-8-5-3-javaclient/324861)

<div class="topic-metadata">

**Author:** [@Abhishek\_Chaurasia](https://discuss.elastic.co/u/Abhishek_Chaurasia)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 6:44am UTC](https://discuss.elastic.co/t/how-to-perform-geodistancesort-on-a-nested-field-using-es-8-5-3-javaclient/324861 "2023-02-07T06:44:09Z")

</div>

We are using ElasticsearchClient instance to build our query and communicate with elasticsearch hosted on elastic-cloud version 8.5.3. We could not find any information on how to inject nested path while creating GeoDis…

---

## [Error=\>logstash Pipeline worker error :"(EACCES) Permission denied](https://discuss.elastic.co/t/error-logstash-pipeline-worker-error-eacces-permission-denied/324788)

<div class="topic-metadata">

**Author:** [@vaibhav.ubale](https://discuss.elastic.co/u/vaibhav.ubale)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 6:26am UTC](https://discuss.elastic.co/t/error-logstash-pipeline-worker-error-eacces-permission-denied/324788 "2023-02-07T06:26:23Z")

</div>

Hi Team/Everyone, I am facing a pipeline error and my pipeline is terminating randomly with error=\>"(EACCES) Permission denied - /var/myrepo/devops/mytask\_watcher.csv" My logstash output conf is as below output { csv…

---

## [Kibana shows Failed to poll for work: Error: work has timed out](https://discuss.elastic.co/t/kibana-shows-failed-to-poll-for-work-error-work-has-timed-out/324447)

<div class="topic-metadata">

**Author:** [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 6:15am UTC](https://discuss.elastic.co/t/kibana-shows-failed-to-poll-for-work-error-work-has-timed-out/324447 "2023-02-07T06:15:48Z")

</div>

Hi there, i've got this log from kibana.log {"type":"log","@timestamp":"2023-02-01T14:48:06+07:00","tags":\["error","plugins","taskManager"\],"pid":57144,"message":"Failed to poll for work: Error: work has timed out"} a…

---

## [Logstash microsoft-sentinel-logstash-output-plugin](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787)

<div class="topic-metadata">

**Author:** [@shadu88](https://discuss.elastic.co/u/shadu88)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/logstash-microsoft-sentinel-logstash-output-plugin/324787 "2023-02-07T05:27:30Z")

</div>

Hello ELKs, Hope you doing well!! has anyone tried IF ELSE condition in "microsoft-sentinel-logstash-output-plugin" output logstash plugin? I'm trying to forward the logs based on log source type to respective DCR en…

---

## [Can use variables for output influxdb db and measurement field?](https://discuss.elastic.co/t/can-use-variables-for-output-influxdb-db-and-measurement-field/324508)

<div class="topic-metadata">

**Author:** [@AlanChan](https://discuss.elastic.co/u/AlanChan)\
**Replies:** 10\
**Last updated:** [February 7, 2023, 5:27am UTC](https://discuss.elastic.co/t/can-use-variables-for-output-influxdb-db-and-measurement-field/324508 "2023-02-07T05:27:16Z")

</div>

Hi I'm wondering if a configuration like this can work or not. filter { mutate { if \[topic\] == "xxxx" { add\_field =\> { "db" =\> "test2", "measurement" =\> "access\_logs" } } else { add\_field =\> { "db…

---

## [How to reset password user elastic](https://discuss.elastic.co/t/how-to-reset-password-user-elastic/324735)

<div class="topic-metadata">

**Author:** [@gugurigon](https://discuss.elastic.co/u/gugurigon)\
**Replies:** 10\
**Last updated:** [February 7, 2023, 5:21am UTC](https://discuss.elastic.co/t/how-to-reset-password-user-elastic/324735 "2023-02-07T05:21:23Z")

</div>

I can't access the elasticsearch to retrieve the information of the cluster. The elasticsearch is run on docker with version 7.x.

---

## [How to include a custom rule variable in Elastic Email alert](https://discuss.elastic.co/t/how-to-include-a-custom-rule-variable-in-elastic-email-alert/324849)

<div class="topic-metadata">

**Author:** [@yoshiouchi](https://discuss.elastic.co/u/yoshiouchi)\
**Replies:** 0\
**Last updated:** [February 7, 2023, 3:55am UTC](https://discuss.elastic.co/t/how-to-include-a-custom-rule-variable-in-elastic-email-alert/324849 "2023-02-07T03:55:47Z")

</div>

I would like to know a way to create a custom rule variable in Elastic Email alert i.e. we have some pre-built variables like {{alertName}} or {{context.group}} but I want to output the name of kubernetes.pod.name in Ela…

---

## [User elasticsearch lost after reboot](https://discuss.elastic.co/t/user-elasticsearch-lost-after-reboot/324839)

<div class="topic-metadata">

**Author:** [@bhirani](https://discuss.elastic.co/u/bhirani)\
**Replies:** 3\
**Last updated:** [February 7, 2023, 3:44am UTC](https://discuss.elastic.co/t/user-elasticsearch-lost-after-reboot/324839 "2023-02-07T03:44:56Z")

</div>

I have installed Elasticsearch on TrueNAS using dpkg. I have setup fs2es-indexer to index my files. I have indexed the files and tested that all works. After reboot, the user elasticsearch is lost. id elasticsearch i…

---

## [Clarification - Upload of CSV file without Date / timestamp file in Kibana](https://discuss.elastic.co/t/clarification-upload-of-csv-file-without-date-timestamp-file-in-kibana/324818)

<div class="topic-metadata">

**Author:** [@Raj4](https://discuss.elastic.co/u/Raj4)\
**Replies:** 2\
**Last updated:** [February 7, 2023, 3:20am UTC](https://discuss.elastic.co/t/clarification-upload-of-csv-file-without-date-timestamp-file-in-kibana/324818 "2023-02-07T03:20:18Z")

</div>

Hi All, Please advise me on the below, I am using Kibana 7.10 version On daily basis I will receive an CSV file (without date/timestamp field), I need to visualize it by comparing the values. Please let me know what …

---

## [ILM doesn't delete indices](https://discuss.elastic.co/t/ilm-doesnt-delete-indices/323983)

<div class="topic-metadata">

**Author:** [@obol89](https://discuss.elastic.co/u/obol89)\
**Replies:** 3\
**Last updated:** [February 7, 2023, 3:00am UTC](https://discuss.elastic.co/t/ilm-doesnt-delete-indices/323983 "2023-02-07T03:00:37Z")

</div>

Hi All, I have a problem with ILM policy that doesn't delete my old indices. I feel like I've checked everything what I could (and I know), but I can't find out why it is not deleting them. I will appreciate your help,…

---

## [How to perform aggregation on nested of nested of nested field?](https://discuss.elastic.co/t/how-to-perform-aggregation-on-nested-of-nested-of-nested-field/324843)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 1\
**Last updated:** [February 7, 2023, 2:05am UTC](https://discuss.elastic.co/t/how-to-perform-aggregation-on-nested-of-nested-of-nested-field/324843 "2023-02-07T02:05:40Z")

</div>

I saw basic examples of how to do a nested aggregation on 1 tiered level of a nested field. But I'm not sure how to perform aggregation when there is more than 1 level of nesting. I tried the following which sets up 2 …

---

## [Migrate from Visualization "Controls" in 7.17 to "Controls" in 8.5](https://discuss.elastic.co/t/migrate-from-visualization-controls-in-7-17-to-controls-in-8-5/324836)

<div class="topic-metadata">

**Author:** [@zvazquez](https://discuss.elastic.co/u/zvazquez)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 11:18pm UTC](https://discuss.elastic.co/t/migrate-from-visualization-controls-in-7-17-to-controls-in-8-5/324836 "2023-02-06T23:18:34Z")

</div>

Hi, We are in the process to upgrade from version 7.17 to version 8.5 and we have realized in our development landscape that the old "controls" visualization is deprecated and the style of the controller certainly looks…

---

## [How to take a snapshot using SSE-C](https://discuss.elastic.co/t/how-to-take-a-snapshot-using-sse-c/324773)

<div class="topic-metadata">

**Author:** [@kannan\_raj](https://discuss.elastic.co/u/kannan_raj)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 8:39am UTC](https://discuss.elastic.co/t/how-to-take-a-snapshot-using-sse-c/324773 "2023-02-06T08:39:19Z")

</div>

Hi All, we are using Elasticsearch version 7.16. I can encrypt the snapshot using SSE-S3(SSE managed by AWS) by adding the configuration "server-side-encryption: true" in the s3 snapshot repository. PUT \_snapshot/my\_s…

---

## [Kibana Crash while loading index list](https://discuss.elastic.co/t/kibana-crash-while-loading-index-list/324795)

<div class="topic-metadata">

**Author:** [@dslavescu](https://discuss.elastic.co/u/dslavescu)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 11:02pm UTC](https://discuss.elastic.co/t/kibana-crash-while-loading-index-list/324795 "2023-02-06T23:02:38Z")

</div>

Hello, I have an ELK Cluster of 3M+12D nodes , with 64GB and 8 cores for the data nodes and a total of 53 TB of data, 3243 indices, 7602 shards. On top, i have a Kibana instance of 8GB RAM + 4 CPU. Both Kibana and ELK a…

---

## [How does elastic agent have it's debug logging turn on without anyone turning it on?](https://discuss.elastic.co/t/how-does-elastic-agent-have-its-debug-logging-turn-on-without-anyone-turning-it-on/324831)

<div class="topic-metadata">

**Author:** [@jerrac](https://discuss.elastic.co/u/jerrac)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 8:24pm UTC](https://discuss.elastic.co/t/how-does-elastic-agent-have-its-debug-logging-turn-on-without-anyone-turning-it-on/324831 "2023-02-06T20:24:25Z")

</div>

Ok, so, I'm not even sure how to search on this one. Right around midnight 1/28-1/29, my fleet server agent had it's debug logging turned on. That server went from 50 docs/min to 60,000 docs/min. Didn't figure it out u…

---

## [Kibana maps don't show information AJAX Error: (500)](https://discuss.elastic.co/t/kibana-maps-dont-show-information-ajax-error-500/324693)

<div class="topic-metadata">

**Author:** [@Saliinger](https://discuss.elastic.co/u/Saliinger)\
**Replies:** 2\
**Last updated:** [February 6, 2023, 8:00pm UTC](https://discuss.elastic.co/t/kibana-maps-dont-show-information-ajax-error-500/324693 "2023-02-06T20:00:28Z")

</div>

Hello! :smiley: Context first: I'm trying to build a Kibana map. I'm giving him coordinates in array format as in this documentation: \[Geopoint Kibana - Docs\] (Geopoint field type | Elasticsearch Guide \[8.6\] | Elastic)…

---

## [NEST create index template](https://discuss.elastic.co/t/nest-create-index-template/324828)

<div class="topic-metadata">

**Author:** [@chachew](https://discuss.elastic.co/u/chachew)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 7:33pm UTC](https://discuss.elastic.co/t/nest-create-index-template/324828 "2023-02-06T19:33:41Z")

</div>

I am running NEST/Elasticsearch 7.13.1 and i cant find in the documentation on how to create an Index Template via the NEST client.

---

## [How to use custom plugin in RestHighLevelClient (migrating from TransportClient to RestHighLevelClient.)](https://discuss.elastic.co/t/how-to-use-custom-plugin-in-resthighlevelclient-migrating-from-transportclient-to-resthighlevelclient/324824)

<div class="topic-metadata">

**Author:** [@hr89](https://discuss.elastic.co/u/hr89)\
**Replies:** 0\
**Last updated:** [February 6, 2023, 7:11pm UTC](https://discuss.elastic.co/t/how-to-use-custom-plugin-in-resthighlevelclient-migrating-from-transportclient-to-resthighlevelclient/324824 "2023-02-06T19:11:23Z")

</div>

Hello Experts! We are in a process of migrating from TransportClient (now, removed) to RestHighLevelClient. We use custom plugin for some functionalities. As per the TransportClient we are initializing it like below. …

---

## [Work with xml in logstash](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784)

<div class="topic-metadata">

**Author:** [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Replies:** 1\
**Last updated:** [February 6, 2023, 7:05pm UTC](https://discuss.elastic.co/t/work-with-xml-in-logstash/324784 "2023-02-06T19:05:39Z")

</div>

Hi all, I have a xml data as below which is harvesting by filebeat and sending to logstash. \<event name="first check"\> \<Data name="id"\> \<Value\>5\</Value\> \</Data\> \<Data name="object\_id"\> \<Value\>123\</Value\> \</Data\> …

[Previous page](https://discuss.elastic.co/c/elastic-stack/81.md?page=641)

[Next page](https://discuss.elastic.co/c/elastic-stack/81.md?page=643)
